package com.example.securitydemo.controller;


import com.example.securitydemo.domain.ResponseResult;
import org.springframework.security.access.prepost.PreAuthorize;
import org.springframework.web.bind.annotation.RequestMapping;
import org.springframework.web.bind.annotation.RestController;

@RestController
public class HelloController {

    @RequestMapping("/hello")
    //@PreAuthorize("hasAuthority('system:dept:list')")
    @PreAuthorize("@xm.xmHasAuthority('system:dept:list')")
    public String hello() {
        return "hello";
    }

    @RequestMapping("/testAuth")
    public ResponseResult testAuth() {
        return new ResponseResult(200, "访问成功");
    }
}
